Share
## https://sploitus.com/exploit?id=WPEX-ID:73BE6E92-EA37-4416-977D-52EE2AFA022A
Put the following payload in any of the plugin's text field settings (such as Title , Title font-size etc): "><svg onload=prompt(1)//

Then save and reload the settings to trigger the XSS. The XSS will also trigger in pages/posts where the plugin's shortcode is embed